Threats
The threat library helps identify and document the causes or events likely to trigger a risk.
Last updated
Was this helpful?
The threat library helps identify and document the causes or events likely to trigger a risk.
In Dastra, a threat represents the triggering factor of a risk: it describes how or why a risk can materialize.
π Threats enrich risk analysis without making its assessment more complex.
The Dastra model is based on a simple and readable chain:
Threat β Risk β Controls β Tests
A threat describes a situation, a behavior or an event
A risk describes the potential impact for the organization
Controls aim to limit the occurrence or the effects of the risk
Tests make it possible to verify the effectiveness of the controls
π Example:
Threat: lack of monitoring of AI logs
Risk: information leakage through AI queries
Controls: logging, monitoring, awareness training
Tests: log review, periodic audits

The threat library centralizes all the identified threats, with:
their name and reference,
their creation date,
filters to facilitate navigation.
π This view makes it possible to:
reuse existing threats,
ensure consistent terminology,
structure coherent risk scenarios.
When creating or editing a threat, the user provides:
the name of the threat
an internal reference
an optional description used to contextualize the threat

The module is deliberately lightweight: threats do not carry a quantified assessment and are not linked directly to controls.
A threat is associated with one or more risks.
This association makes it possible to:
precisely document risk scenarios,
improve the understanding of causes,
strengthen the consistency of the overall analysis.
π The same threat can contribute to several risks, and vice versa.
Using threats makes it possible to have:
a finer and more realistic analysis of risks,
better traceability of scenarios,
clearer communication with stakeholders (CISO, DPO, business teams).
Threats complement the analysis without adding to the operational management burden.
Threats are a clarification tool. They make it possible to better understand the origin of risks, and therefore to better justify the controls that are in place.
Last updated
Was this helpful?
Was this helpful?